Aurora security
Accounts use separate repositories and authenticated access. Passwords are hashed. Invitation and recovery credentials expire and can be redeemed only once. Signing out everywhere invalidates existing sessions.
Private calendar links are treated as credentials. Calendar fetching accepts HTTPS public destinations, does not follow redirects and limits response size and time. Unsupported or failed calendar imports remain visible as connection errors.
Report a vulnerability privately to support@happihacking.com. Include the affected page and a reproducible description using your own account or synthetic data. Please avoid other users' information. We aim to respond within one business day.
The product deployment requires TLS, restricted host access and encrypted off-host backups with a restore rehearsal. Deployment evidence and provider configuration are reviewed before inviting external users. No security system removes every risk; keep a separate copy of information you cannot afford to lose.